IP Library Granted Patent US 10,142,342
Granted Patent B2
US 10,142,342 · App. 14/656,622 · Granted Nov 27, 2018

Authentication of client devices in networks

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,142,342
App. No.
14/656,622
Granted
Nov 27, 2018
Kind
B2
Abstract

Implementations relate to authentication of end devices in networks. In some implementations, a method includes receiving identity information at an edge configuration device from an end device via a connection, where the identity information identifies the end device or one or more users associated with the end device. A request is sent from the edge configuration device to an access control server connected to the network in response to receiving the identity information, where the request requests authentication for the end device. Authentication is received at the edge configuration device from the access control server for the end device to connect to a network connected to the edge configuration device.

Claims (36)

1. A method comprising:

receiving identity information at an edge configuration device from a physical end device via a connection, wherein the identity information identifies the physical end device or one or more users associated with the physical end device, and wherein the identity information includes a request for permission for the physical end device to access a Shortest Path Bridging (SPB) network;

sending a request from the edge configuration device over the SPB network to an access control server connected to the SPB network in response to receiving the identity information, wherein the request requests authentication for the physical end device;

receiving authentication at the edge configuration device from the access control server for the physical end device to connect to the SPB network;

receiving network configuration information at the edge configuration device from the access control server in response to sending the request for authentication; and

using the network configuration information to configure the edge configuration device for use with one or more virtual local area networks (VLANs) of the SPB network for use with the physical end device.

2. The method of claim 1 , wherein the identity information received from the physical end device is received automatically upon connection of the physical end device to the SPB network, wherein the identity information received from the physical end device includes at least one of: a user name, an account name, a password, a MAC address, or descriptive information describing the physical end device.

3. The method of claim 1 , wherein the network configuration information is SPB configuration information.

4. The method of claim 3 , wherein the physical end device is a non-SPB device that is not compatible with the SPB network.

5. The method of claim 4 , wherein the edge configuration device includes a fabric attach agent for processing networking configuration messages, and wherein the physical end device does not include a fabric attach agent and the identity information does not include network configuration information.

6. The method of claim 1 , further comprising sending the network configuration information over the SPB network to an edge server device and receiving information from the edge server device indicating approval of the network configuration information.

7. The method of claim 1 , wherein the authentication is performed by an authentication server included in or in communication with the access control server.

8. The method of claim 1 , wherein the network configuration information received from the access control server includes one or more bindings mapping the one or more VLANs to one or more service identifiers (ISIDs) for the physical end device.

9. The method of claim 1 , wherein the physical end device is a client device comprising a wireless transceiver.

10. A device comprising:

a memory; and

at least one processor configured to access the memory and perform operations comprising:

receiving identity information at an edge configuration device from a physical end device via a connection, wherein the identity information identifies the physical end device or one or more users associated with the physical end device, and wherein the identity information includes a request for permission for the physical end device to access a Shortest Path Bridging (SPB) network;

sending a request from the edge configuration device over the (SPB) network to an access control server connected to the SPB network in response to receiving the identity information, wherein the request requests authentication for the physical end device;

receiving authentication at the edge configuration device from the access control server for the physical end device to connect to the SPB network;

receiving SPB configuration information at the edge configuration device from the access control server in response to sending the request for authentication; and

using the SPB configuration information to configure the edge configuration device for use with one or more virtual local area networks (VLANs) of the SPB network for use with the physical end device.

11. The device of claim 10 , wherein the identity information received from the physical end device is received automatically upon connection of the physical end device to the SPB network, and wherein the identity information received from the physical end device includes at least one of: a user name, an account name, a password, a MAC address, or descriptive information describing the physical end device.

12. The device of claim 10 , the operations further comprising sending the SPB configuration information over the SPB network to an edge server device and receiving information from the edge server device indicating approval of the SPB configuration information.

13. The device of claim 10 , wherein the physical end device is a non-SPB device that is not compatible with the SPB network.

14. The device of claim 13 , wherein the edge configuration device includes a fabric attach agent for processing networking configuration messages, and wherein the physical end device does not include a fabric attach agent and the identity information does not include network configuration information.

15. The device of claim 10 , wherein the SPB configuration information received from the access control server includes one or more bindings mapping the one or more VLANs to one or more service identifiers (ISIDs) for the physical end device.

16. A computer program product comprising a non-transitory computer-readable medium including program instructions to be implemented by a device connected to a communication network, the program instructions performing operations including:

receiving identity information at an edge configuration device from a physical end device via a connection, wherein the identity information identifies the physical end device or one or more users associated with the physical end device, and wherein the identity information includes a request for permission for the physical end device to access a Shortest Path Bridging (SPB) network;

sending a request from the edge configuration device over the (SPB) network to an access control server connected to the SPB network in response to receiving the identity information, wherein the request requests authentication for the physical end device; and

receiving authentication at the edge configuration device from the access control server for the physical end device to connect to the SPB network;

receiving SPB configuration information at the edge configuration device from the access control server in response to sending the request for authentication; and

using the SPB configuration information to configure the edge configuration device for use with one or more virtual local area networks (VLANs) of the SPB network for use with the physical end device.

17. The computer program product of claim 16 , wherein the identity information received from the physical end device is received automatically upon connection of the physical end device to the SPB network, and wherein the identity information received from the physical end device includes at least one of: a user name, an account name, a password, a MAC address, or descriptive information describing the physical end device.

18. The computer program product of claim 16 , the operations further comprising sending the SPB configuration information over the SPB network to an edge server device and receiving information from the edge server device indicating approval of the SPB configuration information.

19. The computer program product of claim 16 , wherein the physical end device is a non-SPB device that is not compatible with the SPB network.

Assignments (9)
AMENDED SECURITY AGREEMENT Recorded Aug 18, 2023
From: EXTREME NETWORKS, INC.; AEROHIVE NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 064782/0971 →
SECURITY INTEREST Recorded May 1, 2018
From: EXTREME NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 046050/0546 →
RELEASE OF SECURITY INTEREST Recorded May 1, 2018
From: SILICON VALLEY BANK
To: EXTREME NETWORKS, INC.
Reel/Frame 046051/0775 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 041576/0001 Recorded Dec 15, 2017
From: CITIBANK, N.A.
To: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS LLC (FORMERLY KNOWN AS OCTEL COMMUNICATIONS CORPORATION); VPNET TECHNOLOGIES, INC.
Reel/Frame 044893/0531 →
THIRD AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 044639/0300 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2017
From: AVAYA INC.; AVAYA COMMUNICATION ISRAEL LTD; AVAYA HOLDINGS LIMITED
To: EXTREME NETWORKS, INC.
Reel/Frame 043569/0047 →
SECOND AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Jul 14, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 043200/0614 →
SECURITY INTEREST Recorded Jan 27, 2017
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS CORPORATION; VPNET TECHNOLOGIES, INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 041576/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 13, 2015
From: SELIGSON, JOHN; KUC, ZENON; MEAD, JOHN
To: AVAYA INC.
Reel/Frame 035156/0459 →
Cited By (2)
US 12,206,552 US 12,386,686